CVE-2023-39176

CVSS 3.1 Score 5.8 of 10 (medium)

Details

Published Nov 18, 2024
CWE ID 125

Summary

CVE-2023-39176 is a newly discovered vulnerability affecting the parsing of SMB2 requests in the Linux kernel's ksmbd module. The flaw arises due to insufficient validation of user-supplied data present in transform headers. An attacker can exploit this issue to read beyond the allocated buffer, potentially disclosing sensitive information. This vulnerability only poses a threat to Linux systems that have ksmbd enabled.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share